2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48085 | CRITICAL | 9.8 | 75.8% | Dec 14, 2023 | Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component ... |
| CVE-2023-48084 | CRITICAL | 9.8 | 33.7% | Dec 14, 2023 | Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool. |
| CVE-2023-44709 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via th... |
| CVE-2023-49937 | CRITICAL | 9.8 | 1.4% | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a ... |
| CVE-2023-49934 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed versio... |
| CVE-2023-31546 | CRITICAL | 9.6 | 49.4% | Dec 14, 2023 | Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature... |
| CVE-2023-40921 | CRITICAL | 9.8 | 0.5% | Dec 14, 2023 | SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to ... |
| CVE-2023-6771 | CRITICAL | 9.8 | 0.6% | Dec 13, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Student Attendance System 1.0... |
| CVE-2023-46727 | CRITICAL | 9.8 | 67.1% | Dec 13, 2023 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI i... |
| CVE-2023-46726 | CRITICAL | 9.8 | 1.3% | Dec 13, 2023 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP... |
| CVE-2023-6765 | CRITICAL | 9.8 | 0.7% | Dec 13, 2023 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical.... |
| CVE-2023-49363 | CRITICAL | 9.8 | 0.7% | Dec 13, 2023 | Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php. |
| CVE-2023-6756 | CRITICAL | 9.8 | 1.3% | Dec 13, 2023 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown functio... |
| CVE-2023-42495 | CRITICAL | 9.8 | 1.5% | Dec 13, 2023 | Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command (... |
| CVE-2023-6723 | CRITICAL | 9.8 | 0.8% | Dec 13, 2023 | An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious fi... |
| CVE-2023-47577 | CRITICAL | 9.8 | 0.7% | Dec 13, 2023 | An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no ch... |
| CVE-2023-50252 | CRITICAL | 9.8 | 23.9% | Dec 12, 2023 | php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that reference... |
| CVE-2023-48225 | CRITICAL | 9.1 | 0.8% | Dec 12, 2023 | Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, an... |
| CVE-2023-43364 | CRITICAL | 9.8 | 2.6% | Dec 12, 2023 | main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution. |
| CVE-2023-6593 | CRITICAL | 9.8 | 0.7% | Dec 12, 2023 | Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker t... |
| CVE-2023-46456 | CRITICAL | 9.8 | 24.7% | Dec 12, 2023 | In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN c... |
| CVE-2023-46454 | CRITICAL | 9.8 | 23.5% | Dec 12, 2023 | In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted p... |
| CVE-2023-48427 | CRITICAL | 9.8 | 0.4% | Dec 12, 2023 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly v... |
| CVE-2023-41117 | CRITICAL | 9.8 | 0.8% | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo... |
| CVE-2023-50424 | CRITICAL | 9.8 | 1.1% | Dec 12, 2023 | SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, al... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now